SAGRILAFT, SARLAFT and PTEE: What They Are and How They Differ
Colombia's three systems against money laundering and corruption, and what changed in 2026.
Talk to us on WhatsApp COX for SAGRILAFT and PTEE See every service
SAGRILAFT is the anti-money laundering system of Colombian companies outside the financial sector, supervised by the Superintendency of Companies. SARLAFT is the system of the entities supervised by the Financial Superintendency. PTEE is the business transparency and ethics programme against corruption and transnational bribery. Since Circular 100-000020 of 2026, SAGRILAFT and PTEE are a single system.
What Each One Is
SAGRILAFT
Self-Control and Comprehensive Risk Management System for money laundering, terrorist financing and financing of the proliferation of weapons of mass destruction (LA/FT/FPADM).
The system that companies of the real sector supervised by the Superintendency of Companies must implement when they meet the thresholds of the rules: identify, measure, control and monitor the risk of being used to launder money or finance terrorism.
SARLAFT
Money Laundering and Terrorist Financing Risk Management System.
The equivalent system for the entities supervised by the Financial Superintendency, such as banks and insurers. It is set out in the Financial Superintendency's own Basic Legal Circular, with different rules and a different supervisor.
PTEE
Business Transparency and Ethics Programme.
The programme against corruption and transnational bribery for companies supervised by the Superintendency of Companies. Until 2026 it ran in parallel with SAGRILAFT, with its own manual and its own officer.
Side by Side
| SAGRILAFT | SARLAFT | PTEE | |
|---|---|---|---|
| Supervisor | Superintendency of Companies | Financial Superintendency | Superintendency of Companies |
| Who applies it | Real-sector companies that meet the thresholds | Supervised financial entities | Real-sector companies that meet the thresholds |
| Risks it covers | Money laundering, terrorist financing and proliferation financing | Money laundering and terrorist financing | Corruption and transnational bribery |
| Where it is set out | Chapter IX of the Superintendency of Companies' Basic Legal Circular, since 2026 | Basic Legal Circular of the Financial Superintendency | Chapter IX of the Superintendency of Companies' Basic Legal Circular, since 2026 |
What Changed in 2026
On 2 July 2026 the Superintendency of Companies issued Circular Externa 100-000020, a new Basic Legal Circular that repealed the previous ones.
SAGRILAFT and PTEE, one system
Both now sit in Chapter IX, in a single system that covers money laundering, terrorist financing and proliferation financing together with corruption and transnational bribery.
One compliance officer, one manual
The role is unified and the governance too: one officer and one integrated manual instead of two programmes with their own documents. The new rules also raise what is required of the officer.
Shared responsibility
Sanctions can reach the company, its directors, the compliance officer and the statutory auditor, not only the legal entity.
Deadline: 31 May 2027
Companies already obligated have until that date to adapt their system. Those that become obligated during 2026 have until 31 May of the following year.
SARLAFT did not change with this circular: it belongs to the Financial Superintendency.
Does My Company Have to Implement It?
It depends on the revenue or the assets at the close of the previous year, with lower thresholds for the sectors considered more exposed. Since 2026 the thresholds are expressed in Basic Value Units (UVB) instead of minimum wages. The more exposed sectors include:
- Real estate agents and companies
- Trade in precious metals and stones
- Legal and accounting services
- Construction and vehicle trade
- Virtual assets
Below the threshold of the full system, the Minimum Measures Regime may apply, which also obliges, with lighter requirements. This guide does not give the thresholds on purpose: check them in the official text of the circular or with your adviser.
What the System Includes
- A compliance officer and a deputy, appointed by the highest corporate body
- An integrated manual with policies, procedures and owners
- Due diligence on counterparties, enhanced for the riskier ones, politically exposed persons included
- Identification of the beneficial owner, with its documentary support
- A risk matrix with a documented methodology
- Suspicious operation reports to the UIAF, and the reports of periods without them
- Periodic training of the staff, with a record of who received it
- Record keeping that lets every decision be reconstructed
The Operation of the System, in COX
One file per counterparty for both fronts of Chapter IX: due diligence, restrictive list and PEP screening, adverse media, a documented risk matrix, training records and an immutable trail of every decision. The manual and the officer stay with your company.
COX for SAGRILAFT and PTEEFrequently Asked Questions
This guide is for informational purposes only and does not constitute legal advice. It summarises Circular Externa 100-000020 of 2026 without replacing it: confirm thresholds, deadlines and requirements in the official text of the Superintendency of Companies or with a Colombian adviser.
Get Ready Before May 2027
Adapting means a new officer profile, one manual instead of two and a new matrix. Start with the files.
Talk to us on WhatsApp See every service Estimate your costs
Explore more COX solutions:
COX for SAGRILAFT and PTEE Restrictive list screening Employee Compliance Training How to implement a whistleblowing channel